From vibe hacking to flat-pack malware

March 2026 Information Security, AI & Data Analytics

HP issued its latest Threat Insights Report, with strong indications that attackers are using AI to scale and accelerate campaigns, and that many are prioritising cost, effort, and efficiency over quality. Despite being formulaic and low-effort, these AI-assisted attacks are slipping past enterprise defences.

The report provides an analysis of real-world cyberattacks, helping organisations keep up with the latest techniques that cybercriminals use to evade detection and breach PCs in the fast-changing cybercrime landscape. Based on the millions of endpoints running HP Wolf Security, notable campaigns identified by HP threat researchers include:

Vibe-hacking scripts using Booking.com redirects: Attackers are using AI to generate ready-made infection scripts – known as vibe-hacking – to automate malware delivery. In one campaign, a link in a fake invoice PDF triggers a silent download from a compromised site before redirecting victims to trusted platforms such as Booking.com.

Flat-pack malware speeds up campaign building: Threat actors are assembling attacks using inexpensive, off-the-shelf malware components, likely purchased from hacker forums. While lures and final payloads change, attackers are reusing the same intermediate scripts and installers, allowing them to quickly build, customise, and scale campaigns with minimal effort. Notably, this is not the work of a single threat group; multiple, unrelated actors are using the same building blocks.

Malware hidden in fake Teams installer ‘piggyback’ attack: Campaigns distributed malware using search engine poisoning and malicious adverts that promote fake Microsoft Teams websites. Victims download a malicious installer bundle in which hidden Oyster Loader malware piggybacks on the Teams installation process, allowing the real app to install, while the infection runs unnoticed, giving the attacker backdoor control of the user’s device.

Alex Holland, principal threat research, HP Security Lab, comments, “It is the c are seeing is that many attackers are optimising for speed and cost rather than quality. They are not using AI to raise the bar; they are using it to move faster and reduce effort. The campaigns themselves are basic, but the uncomfortable reality is they still work.”

The report, which examines data from October-December 2025, details how cybercriminals continue to diversify attack methods to bypass security tools with no reported breaches.

• At least 14% of email threats identified by HP Sure Click bypassed one or more email gateway scanners.

• Executable files were the most popular delivery type (37%), followed by .zip (11%) and .docx (10%).

Dr Ian Pratt, global head of security for personal systems at HP Inc., comments, “AI-assisted attacks are shining a spotlight on the limitations of detection-led security. When attackers can generate and repackage malware in minutes, detection-based defences cannot keep up. Instead of trying to spot every variant, organisations need to reduce exposure. By containing high-risk activities, like opening untrusted attachments or clicking unknown links within an isolated environment, businesses can stop threats before they cause damage and remove an entire class of risk.”

Visit the Threat Research blog to view the report.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The dangers of parked domains
Information Security
Kaspersky warns that fraudsters are exploiting so-called ‘parked domains’ to harvest sensitive personal data from unsuspecting users. These deceptive sites often masquerade as error pages or ad-filled placeholders, exposing users to privacy breaches and potential identity theft.

Read more...
Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Buying more security tools is not building a defence
Information Security
Sophisticated attacks are specifically engineered to bypass individual security tools, and companies absorbing the damage are those who have confused procurement with protection, says Richard Frost from Armata Cyber Security.

Read more...
Modernising ‘smart’ ports
IoT & Automation Information Security Transport (Industry) Logistics (Industry)
A modern port is part of a much larger digital trade ecosystem where all systems need to work together. If one part of that ecosystem is disrupted, the impact can quickly move through the supply chain.

Read more...
Reinventing cybersecurity
NEC XON News & Events Information Security Commercial (Industry)
NEC XON helps a workforce solutions leader reinvent cybersecurity with an AI-enhanced XDR solution to keep pace with increasingly devious cyberattack techniques, including fileless malware, lateral movement, and credential misuse.

Read more...
Hold the line
BlueVision Information Security Editor's Choice
While most businesses are still focused on guarding the wall, the perimeter today has moved to the login screen, according to Christo Coetzer, founder and managing director of BlueVision Technologies.

Read more...
Attackers are turning AI to their advantage
Information Security AI & Data Analytics
ESET's H1 2026 Threat Report analysed around 900 000 AI skills and found more than 3000 to be outright malicious, exposing a fast-growing attack surface for organisations experimenting with AI.

Read more...
BlueVision launches Fusion Cloud
BlueVision Information Security Products & Solutions
Most businesses have moved to the cloud, including Microsoft 365, Azure, AWS and more, and in doing so assume they're protected because they're using a reputable platform; however, the reality is somewhat different.

Read more...
Tools detect threats: Cyber resilience protects businesses
Information Security
If your cybersecurity strategy is built around buying Managed Detection and Response (MDR), deploying an Endpoint Detection and Response (EDR) agent, and calling it ‘done’, then someone has sold you a story, not a strategy.

Read more...
Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.